Asking the board the right questions and setting up your CISO for success
It is the responsibility of the CEO and the board to discuss the following questions in to achieve cyber resilience:
- Do we have a collaborative approach to emerging cyber-risk issues? Consider whether or not the top executives in charge of developing risk management strategies and resilience are working together with the CISO toward a single objective of achieving success.
- How responsive and adaptable are we in the face of cyber threats and our management of them? Cyber risk might still be considered an IT problem, or lack integration with enterprise risk management processes, or just be seen as a compliance exercise (for example, achieving an ISO 27001:2013 certification). However, this is not enough to enable and build effective cyber resilience. Senior management should take a close look at cyber risk and collaborate to identify, quantify, treat, and transfer that cyber risk. They also should...